PoC Index

CVE-2021-42237

KEV RANSOMWAREHIGH 10.0EPSS 97.9%

Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is required to exploit this vulnerability.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
97.90% chance of exploitation in the next 30 days, 100th percentile
CISA KEV
added 2022-03-25, used in ransomware campaigns
Nuclei
critical · CWE-502
Published
2021-11-05
Updated
2026-07-09

Proof-of-concept exploits (3)

Nuclei templates (1)

Metasploit modules (1)

References

Related